feat: update CORS and CSRF trusted origins for improved security #68

Merged
Saani merged 1 commits from feature/meetings into main 2025-12-05 12:54:07 +00:00

View File

@ -15,14 +15,17 @@ DEBUG = os.getenv('DEBUG', 'False').lower() == 'true'
ALLOWED_HOSTS = os.getenv('ALLOWED_HOSTS', '*').split(',') ALLOWED_HOSTS = os.getenv('ALLOWED_HOSTS', '*').split(',')
CORS_ALLOWED_ORIGINS = [ CORS_ALLOWED_ORIGINS = [
'https://attunehearttherapy.com' 'https://attunehearttherapy.com',
'https://www.attunehearttherapy.com',
'https://api.attunehearttherapy.com',
] ]
CORS_ALLOW_CREDENTIALS = True CORS_ALLOW_CREDENTIALS = True
CSRF_TRUSTED_ORIGINS = [ CSRF_TRUSTED_ORIGINS = [
'https://api.attunehearttherapy.com', 'https://api.attunehearttherapy.com',
'https://attunehearttherapy.com' 'https://attunehearttherapy.com',
'https://www.attunehearttherapy.com',
] ]
INSTALLED_APPS = [ INSTALLED_APPS = [